Splunk Enterprise

Why am I getting these socket errors?

tkwaller_2
Communicator

HttpListener - Socket error from while accessing /services/streams/search: Broken pipe?

Here's my ulimit info
ulimit -a
core file size (blocks, -c) 0
data seg size (kbytes, -d) unlimited
scheduling priority (-e) 0
file size (blocks, -f) unlimited
pending signals (-i) 31866
max locked memory (kbytes, -l) 64
max memory size (kbytes, -m) unlimited
open files (-n) 10240
pipe size (512 bytes, -p) 8
POSIX message queues (bytes, -q) 819200
real-time priority (-r) 0
stack size (kbytes, -s) 8192
cpu time (seconds, -t) unlimited
max user processes (-u) 31866
virtual memory (kbytes, -v) unlimited
file locks (-x) unlimited

Please help!

0 Karma

ccl0utier
Splunk Employee
Splunk Employee

I suggest you check the following Splunk answer: https://answers.splunk.com/answers/105292/what-is-the-cause-of-these-socket-errors-reported-in-splun...

I'd then check your splunkd.log logs for anything mentioning a limit being hit or something that might help explain that behaviour (probably for the HTTPListener component).

As a last resort, you might want to do a network trace (Wireshark, NetMon, etc...) with or without the help of your network team. That should help you see what is happening from the network side and might help direct where to look for the issue's root cause next.

0 Karma

hettervik
Builder

Hi! Did you ever find out why you were getting the broken pipe warning? I've seem to have encountered the same problem. One observation from my side is that I'm low on free RAM on the machine, but I don't know if this is related or not.

0 Karma
Get Updates on the Splunk Community!

From GPU to Application: Monitoring Cisco AI Infrastructure with Splunk Observability ...

AI workloads are different. They demand specialized infrastructure—powerful GPUs, enterprise-grade networking, ...

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...

Index This | What goes up and never comes down?

January 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...